Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109600. PoCs published by SajjadBnd.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file download vulnerability in MPC Sharj 3.11.1 Beta via the 'download.php' script. The vulnerability arises from improper handling of the 'id' parameter, allowing an attacker to read arbitrary files by encoding the path in base64 and reversing it.
Description
MPC Sharj 3.11.1 - Arbitrary File Download
Exploits (1)
This exploit demonstrates an arbitrary file download vulnerability in MPC Sharj 3.11.1 Beta via the 'download.php' script. The vulnerability arises from improper handling of the 'id' parameter, allowing an attacker to read arbitrary files by encoding the path in base64 and reversing it.